Legal
Privacy Policy
Draft — under legal review while the full data-flow inventory is completed, and not yet binding. This page describes the intended approach; the final version will replace it after review.
1. Our approach
Verazyn is designed to keep you in control of your data. This policy will explain exactly what we collect, why, and how you can control it. Until the final version is published, treat this as a description of intent.
2. What we collect
Account details you provide, the rules and evidence you create, and operational data needed to run the service. We aim to collect the minimum necessary.
3. Your AI provider and model keys
In local mode, your requests go directly from your machine to your AI provider — Verazyn is not in the path and does not proxy that traffic. Your provider's own privacy terms apply to those requests.
4. How we use data
To operate, secure, and improve the service, and to provide support. We do not sell your personal data.
5. Sharing and subprocessors
We use a limited set of subprocessors to run the service. The final policy will list them, along with data residency and retention details.
6. Your rights and choices
You can access, export, and delete your data. The final policy will describe how to exercise each right and the applicable regional protections.
7. Security
We protect data with encryption in transit and at rest and role-based access. Security review evidence is being assembled as the enterprise-readiness gates close — it is not presented as a completed certification.